Логотип exploitDog
bind:CVE-2022-24128
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-24128

Количество 4

Количество 4

nvd логотип

CVE-2022-24128

почти 4 года назад

Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The installation process uses commands such as CREATE x IF NOT EXIST that allow an unprivileged user to precreate objects. These objects will be used by the installer (which executes as Superuser), leading to privilege escalation. In order to be able to take advantage of this, an unprivileged user would need to be able to create objects in a database and then get a Superuser to install TimescaleDB into their database. (In the fixed versions, the installation aborts when it finds that an object already exists.)

CVSS3: 8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2023:0053-1

почти 3 года назад

Security update for timescaledb

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2023:0046-1

почти 3 года назад

Security update for timescaledb

EPSS: Низкий
github логотип

GHSA-9cr2-2mw7-2c7r

почти 4 года назад

Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation.

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-24128

Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The installation process uses commands such as CREATE x IF NOT EXIST that allow an unprivileged user to precreate objects. These objects will be used by the installer (which executes as Superuser), leading to privilege escalation. In order to be able to take advantage of this, an unprivileged user would need to be able to create objects in a database and then get a Superuser to install TimescaleDB into their database. (In the fixed versions, the installation aborts when it finds that an object already exists.)

CVSS3: 8
0%
Низкий
почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2023:0053-1

Security update for timescaledb

0%
Низкий
почти 3 года назад
suse-cvrf логотип
openSUSE-SU-2023:0046-1

Security update for timescaledb

0%
Низкий
почти 3 года назад
github логотип
GHSA-9cr2-2mw7-2c7r

Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation.

CVSS3: 8
0%
Низкий
почти 4 года назад

Уязвимостей на страницу